Every lesson in the Cryptography slide course, in full text: 25 decks, 1591 slides.
Chapter 1: Overview of Cryptography and Its ApplicationsChapter 1 of Trappe & Washington: the Alice-Bob-Eve scenario, Eve's four goals, the four attack models, Kerckhoffs's principle, and the split between symmetric and public key cryptography — with RSA, ElGamal, NTRU and McEliece each introduced through the hard problem it rests on. Closes on the chapter's central argument, that key length bounds brute force and nothing else.
Chapter 2: Classical CryptosystemsChapter 2 of Trappe & Washington: the shift, affine, Vigenère, substitution, Playfair, ADFGX and Enigma ciphers, each with its own worked encryption and its own break. Builds the frequency-analysis and coincidence-counting toolkit, and argues the chapter's thesis — that ciphers fall to structure, not to the size of their key space.
Chapter 3: Basic Number TheoryChapter 3 of Trappe & Washington: the Euclidean and extended Euclidean algorithms, congruences and modular inverses, the Chinese Remainder Theorem, square-and-multiply exponentiation, Fermat's and Euler's theorems with the totient, primitive roots, matrices and square roots mod n, the Legendre and Jacobi symbols, finite fields including the GF(2^8) of AES, and continued fractions. Every worked example is the book's own and is verified numerically.
Chapter 4: The One-Time PadChapter 4 of Trappe & Washington: binary and ASCII encoding, the one-time pad and its XOR arithmetic, the total collapse that follows reusing a pad, perfect secrecy defined through conditional probability and proved for the pad, the counting bound that makes perfect secrecy impossible for any short-key system, and the ciphertext indistinguishability game that becomes the book's working definition of security.
Chapter 5: Stream CiphersChapter 5 of Trappe & Washington: pseudorandom bit generation from linear congruential generators, one-way functions and the Blum-Blum-Shub quadratic residue generator; linear feedback shift registers, their periods, and the known-plaintext attack that recovers a length-m recurrence from 2m bits by linear algebra over GF(2); and RC4's key scheduling and generation algorithms together with the biases that ended its deployment.
Chapter 6: Block CiphersChapter 6 of Trappe & Washington: block ciphers as keyed permutations, the Hill cipher and its determinant condition, and the five modes of operation — ECB, CBC, CFB, OFB and CTR — each with its own slide, its feedback path, its IV or nonce requirement and its error-propagation behaviour. Closes on multiple encryption and the meet-in-the-middle attack that reduces double encryption from 2^112 to roughly 2^57.
Chapter 7: The Data Encryption StandardChapter 7 of Trappe & Washington: the Feistel structure and the one-line proof that it is invertible for any round function; the book's simplified 12-bit DES worked by hand through its expander, S-boxes and key schedule; differential cryptanalysis on three rounds and why XORing two plaintexts cancels the key; the full DES with its 64-bit block, 56-bit key and eight S-boxes; the twenty-one-year story of how its key length aged; and password hashing with salts.
Chapter 8: The Advanced Encryption Standard (Rijndael)Chapter 8 of Trappe & Washington: AES as ten to fourteen rounds of four layers on a 4x4 byte state, with SubBytes, ShiftRows, MixColumns and AddRoundKey each given its own slide and its own worked example. Covers the GF(2^8) arithmetic the cipher runs on, the inversion of every layer including InvMixColumns, the reason the final round omits MixColumns, and Section 8.4's published design rationale — the S-box built algebraically to avoid DES's trapdoor suspicions, and a round count set at the attack frontier plus four.
Chapter 9: The RSA AlgorithmChapter 9 of Trappe & Washington: RSA set up and worked through with the book's own numbers, its four-line correctness proof from Euler's theorem, and the equivalence of factoring, computing phi(n) and finding d. Covers the Fermat, Miller-Rabin and Solovay-Strassen compositeness tests; Fermat factorization, Pollard's p-1 method and the x^2 = y^2 principle behind the quadratic sieve; the low-exponent and Wiener attacks that break RSA without factoring anything; the RSA-129 challenge; and treaty verification, which is a digital signature three chapters early.
Chapter 10: Discrete LogarithmsChapter 10 of Trappe & Washington: the discrete logarithm problem and the free parity bit; the Pohlig-Hellman algorithm worked through the book's own example mod 41; baby step giant step as a time-memory trade; index calculus and why its absence in elliptic curve groups is worth a factor of twelve in key size; bit commitment with its hiding and binding requirements; Diffie-Hellman key exchange together with the intruder-in-the-middle attack it does not resist; and the ElGamal cryptosystem, whose security reduces to the Computational Diffie-Hellman problem.
Chapter 11: Hash FunctionsChapter 11 of Trappe & Washington: the three defining properties of a cryptographic hash and why collision resistance implies preimage resistance; the toy XOR hash broken three ways; the discrete log hash and its provable-but-unusable trade; the Merkle-Damgard construction together with the length extension attack that follows from outputting the internal state; SHA-2's compression function; and the sponge construction behind SHA-3, whose hidden capacity removes length extension structurally.
Chapter 12: Hash Functions — Attacks and ApplicationsChapter 12 of Trappe & Washington: the birthday paradox derived from the book's own numbers and turned into the 2^(n/2) collision bound that sets digest, block, nonce and group sizes; Joux's multicollisions and why concatenating two hashes buys almost nothing; the random oracle model; hash-based stream encryption; HMAC and precisely which attack its outer hash prevents; password protocols and their three separate failures; and hash pointers, Merkle trees and blockchains, together with the agreement problem hashing cannot solve.
Chapter 13: Digital SignaturesChapter 13 of Trappe & Washington: RSA signatures and the existential forgery they permit; blind signatures built on RSA's multiplicativity; the ElGamal signature scheme with its verification proof; why hashing before signing is a security requirement rather than an optimisation; the birthday attack that forces a digest twice the security level; and the Digital Signature Algorithm, whose prime-order subgroup shrinks signatures eightfold — together with the demonstration that reusing the random nonce hands over the private key outright.
Chapter 14: What Can Go WrongChapter 14 of Trappe & Washington: three case studies in which the cryptography was sound and the system failed anyway. Enigma's no-self-map guarantee and the 1941 intercept that exploited it; three ways of choosing RSA primes badly, from Netscape's timestamp seed to the 2012 surveys that found 26 965 moduli sharing a factor; and WEP in full — a 24-bit IV colliding after four thousand packets, a related-key structure, and a linear CRC used where a message authentication code was needed.
Chapter 15: Security ProtocolsChapter 15 of Trappe & Washington: the intruder-in-the-middle attack, illustrated by the book's two-grandmasters story, and the protocols built to prevent it. Key pre-distribution and its quadratic cost, the Blom scheme with its exact collusion threshold, authenticated key agreement, Kerberos through Cliff, Trent, Grant and Serge, public key infrastructure and X.509 chains of trust, PGP's web of trust, the SSL and TLS handshake and record protocols, and the Secure Electronic Transaction dual signature.
Chapter 16: Digital CashChapter 16 of Trappe & Washington: the four requirements of digital cash and why an electronic object loses the one a physical coin gets free; Brands' scheme built on restricted blind signatures, where one spend hides the spender's identity and two spends reveal it automatically; Bitcoin's five stages, proof of work, and mining; and the boundary this chapter draws between what a cryptocurrency guarantees cryptographically — unforgeability, tamper-evidence, committed blocks — and what it assumes economically, namely that honest participants outspend any attacker.
Chapter 17: Secret Sharing SchemesChapter 17 of Trappe & Washington: secret splitting among m people using uniform random masks, the definition of a (t, w) threshold scheme, and Shamir's construction placing the secret at the constant term of a random degree t−1 polynomial recovered by Lagrange interpolation over a finite field. Includes the information-theoretic security proof — every candidate secret is consistent with exactly one polynomial — Blakley's geometric alternative, and the polynomial-reuse failure that leaks the difference of two secrets to any single shareholder.
Chapter 18: GamesChapter 18 of Trappe & Washington: flipping a coin over the telephone using the four square roots of a square modulo pq, where Alice's fairness is information-theoretic and Bob's honesty rests on factoring; and mental poker dealt with no dealer, built from commutative encryption by exponentiation, including the discard audit that works by adding a second lock. Covers both protocols' limitations — the quadratic residue leak and the abort problem that no two-party protocol can solve.
Chapter 19: Zero-Knowledge TechniquesChapter 19 of Trappe & Washington: proving knowledge of a secret while revealing nothing reusable. Covers the Quisquater-Guillou-Berson tunnel and the commit-challenge-respond skeleton, the three properties with the simulator argument for zero-knowledge, the square-root protocol and why answering both challenges is equivalent to knowing the secret, the Feige-Fiat-Shamir identification scheme with its 2^-kt soundness bound and Arthur's identity-derived setup, and the discrete-log and Schnorr schemes from the exercises — including the nonce-reuse algebra that recovers the secret and the Fiat-Shamir transform that turns any of them into a signature.
Chapter 20: Information TheoryChapter 20 of Trappe & Washington: Shannon's measure of uncertainty and what it settles about secrecy. Covers the four requirements that force the entropy formula, joint and conditional entropy with the chain rule and the three standard inequalities, Huffman codes and the H <= L < H+1 compression bound, perfect secrecy defined as H(P|C) = H(P) with the one-time pad proof and the general two-condition theorem, the entropy of English measured by Shannon's prediction experiment, redundancy, and unicity distance — plus the boundary the chapter draws, that RSA has H(P|C) = 0 and is secure anyway.
Chapter 21: Elliptic CurvesChapter 21 of Trappe & Washington: the chord-and-tangent group law with worked chord and tangent computations, the point at infinity and negation, curves modulo p and Hasse's theorem, the elliptic curve discrete logarithm problem and why index calculus has no analogue, Koblitz encoding of messages as points, Lenstra's factorisation method and its unification with the p-1 method and trial division on singular curves, curves in characteristic 2 over GF(2^n), and the translation table that rebuilds ElGamal, Diffie-Hellman and ElGamal signatures on a curve — with every numeric example from the book verified.
Chapter 22: Pairing-Based CryptographyChapter 22 of Trappe & Washington: bilinear pairings on a supersingular curve and what one extra operation makes possible. Covers the five facts and Assumption (A), why a pairing must be computable from coordinates rather than defined by bilinearity, the MOV attack reducing curve discrete logs to a field, Joux's one-round tripartite Diffie-Hellman, Boneh-Franklin identity-based encryption with its inherent key escrow, BLS signatures and the Zhang-Safavi-Naini-Susilo variation, Hess identity-based signatures, and Boneh-Di Crescenzo-Ostrovsky-Persiano encrypted keyword search — all derived from the single identity that moves a secret across the pairing.
Chapter 23: Lattice MethodsChapter 23 of Trappe & Washington: lattices as both a cryptanalytic tool and a cryptographic foundation. Covers bases and the determinant, exact two-dimensional reduction with the proof that its first vector is shortest, the LLL algorithm and its three guarantees, Coppersmith's attack recovering a stereotyped plaintext from low-exponent RSA without factoring, NTRU over convolution polynomials with a fully worked round trip and its interpretation as a short vector in a 2N-dimensional lattice, the GGH cryptosystem where the trapdoor is a choice of basis, the Closest Vector Problem, and the post-quantum motivation — with every numeric example verified.
Chapter 24: Error Correcting CodesChapter 24 of Trappe & Washington, the book's longest: repetition, parity, two-dimensional parity, Hamming, ISBN and Hadamard codes with their code rates; the general theory of (n, M, d) codes, Hamming distance and the detect-s / correct-t thresholds; the Singleton, sphere-packing and Gilbert-Varshamov bounds with MDS and perfect codes; linear codes with generator and parity check matrices, syndrome decoding and duals; Golay, cyclic, BCH and Reed-Solomon codes; and the McEliece cryptosystem, whose trapdoor is an efficient decoder for a disguised Goppa code — with every numeric example verified.
Chapter 25: Quantum Techniques in CryptographyChapter 25 of Trappe & Washington, the final chapter: the three-polarizer experiment and the mathematics of photon polarization and qubits; quantum key distribution with the 25% error rate that betrays an eavesdropper; what a quantum computer does with a superposition and why measurement is the bottleneck; the discrete and quantum Fourier transforms as period finders; and Shor's algorithm worked end to end on n = 21 — the collapse to a residue class, the peaks at 85, 171, 341 and 427, the continued-fraction step giving r = 6, and the classical gcd finish. Closes with what a quantum computer would and would not break across the whole course.
Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.